Skip to content
/ IoCs Public

Files

Latest commit

bd83a7a · Jun 6, 2024

History

History
10 lines (10 loc) · 850 Bytes

crimson_palace_stac1870_bravo.csv

File metadata and controls

10 lines (10 loc) · 850 Bytes
1
IndicatorDataNotes
2
sha25692e2dafb6d91ac7bc725e680d53cfbfcc854033d14f6e4807fd0169c605324d23.ps1 (PowerShell script)
3
sha256DCC938AF8FB2964A1F35ADFB221DE76FFC0BD0CCAAC91455B3638FD4DC33E8C0EvtxParser.exe (EVTX dump)
4
sha2560c3baa012cdb518982ec4ae954b395f3d6b9544ead8e050370219fa584f74f3c2.vbs (VBS script)
5
sha256c679a2453697c51776b8a64d59fb8bf4172906e9a4f91b3872774bd05378d28cr.vbs (VBS script)
6
sha256edd0c859424ab953a92ef20cfc8b938f469253122485915d6de80d314b18b08fmscorsvc.dll (CCoreDoor)
7
sha25655277d86c0707459500dbb16915665ae611d3a4e4597d51599ea8b8fe6f85f29mscorsvc.dll (CCoreDoor)
8
sha256a70e8317a608dd6ea0ad8564b089a153a7e3ab7ef763899d3d806141e820148entpsapi.dll (signed, benign, ntdll.dll used for EDR unhooking)
9
domainmessage.ooguy.comCCoreDoor C2
10
ip146.190.93.250CCoreDoor C2